Meta’s Muse: The Agent Becomes the Control Point

Three weeks ago I argued that Meta would stay upstream as a preference and affinity layer and leave checkout to retailers. Half of that held. Meta is not taking checkout from retailers. But Muse is more than a preference layer. It is an attempt to build a new orchestration point, one that sits between the consumer, the merchant, the wallet, and the payment network.

The shift I am watching is from wallet-centric commerce, where the merchant owns the interaction and presents payment choices, to agent-centric commerce, where the agent orchestrates merchant, wallet, credential, and transaction. If that shift happens at scale, Visa, Mastercard, Stripe, PayPal, banks, and wallets become services the agent can use. Meta owns the consumer relationship and the purchase intent, which is worth more.

What Meta Built in Three Weeks

Date (2026)Event
Sep 8Muse launches in the US with Stripe Link’s wallet for agents
Sep 20–21Amazon blocks Muse from Amazon.com
Sep 22PayPal enabled in Muse
Sep 23Connect: Walmart, Best Buy, Gap, Sephora, Wayfair and others added as connectors; Muse Charm hardware shown; Zuckerberg says Meta will “profit by taking a small fee from transactions”
Sep 24Shop Pay live as a Muse wallet

Goldman Sachs counts over 2.8 million downloads and a number one ranking among free US iOS apps in the second week (Eric Sheridan et al., Goldman Sachs, “Entering the Agentic AI Era for the Commerce Landscape,” Sep 2026). That is early traction, not proof of commerce volume. Nobody has published purchase data.

Stripe Link: Acceptance Without a Network

Muse launched with one payment partner, and the choice tells you the strategy. Link has over 300 million users and is accepted at more than one million businesses. Where Link is accepted, Muse checks out with the consumer’s saved method. Where it is not, Link issues a single-use virtual card scoped to the approved purchase. The consumer approves the total in chat, and Muse never sees the underlying credential.

Three things follow.

  1. Cards win. Link is a wallet of cards and bank accounts, and the fallback is a card. Meta gets broad acceptance on day one without building a payment network, signing acquirers, or asking a merchant to integrate anything.
  2. Meta rents the rails. Goldman’s read is that the implementation “prioritiz[es] time to market over being at the frontier of technical innovation in payments,” and that the card ecosystem “is the default platform on which agentic payments are being built” (Sheridan, Goldman Sachs, Sep 2026). I agree. Meta did not need a network. It needed acceptance.
  3. The agent chooses the credential. Today Muse offers Link, a saved card behind the shopper’s own login, Shop Pay, and PayPal. Once the agent holds several wallets, it decides which one to use. Merchant selection, wallet choice, credential selection, loyalty, and financing all become decisions the agent can steer.

Point three is the control point. In wallet-centric commerce, the merchant page decides which buttons appear and in what order. That is why the fight over checkout button placement has been so fierce for a decade. UBS estimates Apple Pay, Shop Pay, and BNPL are taking 150–200 bps of global ecommerce checkout share a year from 2025 to 2030 (Timothy Chiodo, UBS, “Assessing Branded Checkout Competition,” Apr 2026). In agent-centric commerce the button order stops mattering, because the agent never sees the buttons.

Wallet-centricAgent-centric
Who owns the interactionMerchantAgent
Who presents payment choiceMerchant checkout pageAgent, on the consumer’s behalf
How wallets competeButton placement, conversion liftSelection by the agent
Where intent is capturedSearch, ads, merchant siteConversation with the agent
Role of networks and walletsBrands the consumer picksServices the agent calls

Amazon Blocked, Walmart Connected

Amazon and Walmart made the choices I expected when I wrote about their two different bets on agentic commerce in March.

Amazon cut Muse off within two weeks of launch. Shoppers saw a popup: “Continued access by an unauthorized AI agent violates Amazon’s Conditions of Use.” Amazon’s complaints were that Meta never asked, that the agent does not identify itself while browsing, and that it appears to store customer credentials (Todd Bishop, GeekWire, Sep 2026). Goldman ties the block to “first-party data, retail media economics, loyalty programs, and customer ownership.” Amazon controls the agent, the checkout, and the payment. It has no reason to let another agent own the customer, and every reason to protect a retail media business that depends on shoppers landing on Amazon pages.

Walmart went the other way. Three days after the block, Meta announced Walmart as a Muse connector. This came after Walmart pulled back from agentic checkout with OpenAI, “citing challenges in presenting accurate information, preserving brand identity, and managing liability,” with agent-initiated checkout converting about three times worse than referral traffic (Timothy Chiodo, UBS, “Stripe Sessions 2026 Recap,” May 2026). BofA puts the same 3x figure on OpenAI’s Instant Checkout pause in March (Matthew O’Neill, BofA Global Research, “Visa Inc.,” May 2026). I covered why in Explaining the Death of OpenAI’s Instant Checkout: merchants own the fraud risk, and they would not hand it to a black box.

So why say yes to Meta? Because the terms are different. On every Muse payment rail the retailer stays merchant of record, and refunds and disputes run through its existing flow. Walmart gets demand from Meta’s audience and keeps the transaction.

Why Stripe Matters for Walmart

The part of the Stripe relationship that gets the least attention is what Walmart needs to accept an agent’s order. A single-use virtual card alone is a weak signal. The merchant sees a guest card-not-present order on a new card number, with none of the device telemetry its risk stack is built on. Goldman flags the two-step flow as raising the question of “who is liable for fraud/chargebacks.” For a tier-one merchant that runs its own risk engine, that is the objection that killed Instant Checkout.

Stripe’s Agentic Commerce Protocol (ACP) addresses it. ACP issues a Shared Payment Token scoped to one merchant and a maximum amount, and carries Stripe’s device graph and Radar risk signals with it. The merchant receives the token plus the device and risk data it would otherwise have collected itself, and runs its own authorization. As I wrote last October, it lets merchants “operate the way they do today.” It remains the only operable framework today that hands a large merchant both a scoped credential and the risk data needed to run the payment itself.

Meta and Walmart have not said which path the Walmart connector uses, and Goldman notes Stripe has recently leaned on the Link wallet more than on ACP for Muse. But ACP is the path that fits Walmart’s requirements, and it is why the Stripe relationship matters beyond Link acceptance.

Stripe: The Real Threat to Cards

Cards won the launch. That does not mean cards win the decade. Stripe is the one party in this stack positioned to route around the networks. Look at what Stripe holds in a Muse purchase. It holds the consumer wallet (Link). It issues the credential the agent uses (a single-use card or a Shared Payment Token). It supplies the risk signals the merchant relies on (device graph, Radar). In many cases it also processes for the merchant. That is both ends of the transaction plus the trust layer, which is the role a network plays.

The funding source under a Link token is already Stripe’s choice to make with the consumer. Link wallets hold cards and bank accounts, and the token is “backed by the cards and bank accounts already in the wallet” (Chiodo, UBS, May 2026). When ACP launched I noted it is rail agnostic: it works for pay by bank, Pix, or any rail where Stripe’s device graph and Radar work. Since then Link has added Pix and stablecoins, Stripe pays out in stablecoins to 160 countries, and with Tempo it launched the Machine Payments Protocol. Radar now covers payments processed off Stripe.

Put those together. When the agent picks the credential and Stripe supplies the risk decision, a bank account or stablecoin balance in Link is as good as a card to the merchant, and cheaper. The consumer never sees a button. The merchant sees a Stripe token with Stripe’s risk data. The network becomes optional.

Stripe is not doing this today. Cards are the default because they carry chargeback rights and universal acceptance. But the capability is in place, and Stripe sells directly to the merchants who would benefit from cheaper rails.

US Banks Finally Face Real Pressure

This is the first time US banks face real pressure to move on the networks’ agentic programs. Visa and Mastercard have built the pieces: agentic tokens, agent registries, Visa’s Trusted Agent Protocol, Mastercard Agent Pay and Verifiable Intent. Mastercard Agent Pay is live across all US Mastercard cards, with Citi and US Bank named, and it is the one construct that places agent transactions inside existing network liability rules. Visa’s Trusted Agent Protocol is in early production with about 30 issuers, and agentic liability is unaddressed (Starpoint LLP, “Appendix A: Active Identity Efforts,” Jul 2026).

The gap is the issuer. Network agentic tokens only work if banks provision them, authenticate the consumer, and accept liability for the authenticated transaction. In March I argued that banks want to price that service, and that a 5 bps 3DS fee does not pay for a full liability shift. That standoff was affordable while the alternative was nothing.

It is not affordable now. If issuers do not support network agentic credentials, Stripe already has a working answer: its own token, its own risk data, its own wallet, and a growing set of non-card funding options. Every quarter banks spend negotiating the fee is a quarter Link spends signing up consumers and merchants to a model where the bank is a funding source behind a Stripe token. If Visa and Mastercard cannot bring the issuers along, Stripe will do it without them. For the first time, the cost of waiting falls on the banks.

Meta Is Not Taking Checkout from Merchant. Google Is (Trying to).

This is Meta’s biggest strategic advantage over Google. Meta is leaving the transaction with the retailer. It takes the demand and the intent, which it already monetizes, and plans to earn “a small fee from transactions.” No rate, date, or payer has been disclosed. A fee is a toll, and retailers will judge Meta by where it lands. But a toll on a transaction the retailer still owns is a smaller ask than a buy button that takes the customer away.

OpenAI tried to own checkout and retreated. Amazon owns checkout and blocks outside agents. Google is building its own checkout. Meta is the only horizontal agent that has offered retailers the demand without the checkout.

Meta’s Ad Business Is Not Google’s

Google and Meta both sell advertising, but they sell different things, and the difference matters in agentic commerce. Google sells declared intent. A consumer types a query, Google matches an ad to it, and the session ends when the consumer clicks through. The value is in the moment: high intent, short interaction. That is why Google wants the buy button. If the query is the asset, closing the sale on the spot captures more of it.

Meta sells influence over time. Its business was never built on a query. It is built on hours of scrolling, following, saving, and sharing, and on predicting intent before the consumer states it. As I noted on September 8, Advantage+ already weighs more than 10,000 real-time signals per impression.

A conversational agent extends Meta’s model, not Google’s. A Muse session is long and multi-turn: planning a trip, building an outfit, restocking a pantry. Muse remembers what a user shared once and can turn a saved Instagram recipe reel into a grocery list (Meta, via Fortune, Sep 2026). Each turn is a chance to shape which merchant, product, and brand the consumer picks. Google gets the query. Meta gets the conversation around it.

There is a limit. Meta says Muse conversations and data will not be shared with its advertising systems. If that holds, the influence shows up in Muse’s recommendations and the transaction fee, not in ad targeting. That is a cleaner business than ads, and a harder one for merchants to audit.

Muse Charm: The Trust Endpoint

Muse Charm looked like a gimmick at Connect: a keychain-sized device with a screen, camera, microphones, and a fingerprint sensor, shipping “in time for the holidays in December” (Jacob Kastrenakes, The Verge, Sep 2026). It makes strategic sense. Meta’s is addressing a key gap in Android Architecture. While Google “controls” Android, but hardware security varies by manufacturer, and a Titan M2 on a Pixel says nothing about the phone next to it. Meta needs a device bound trust anchor with terms it can own.

Dedicated hardware solves that. Meta controls the silicon, the operating system, the biometric, and the key storage. That gives it a device-bound identity and encryption layer it defines end to end, consistent across every unit it ships, which Android cannot promise across all its devices.

That layer matters because an agent needs a way to sign a transaction. My paper on digital payment credentials (background in EMVCo and DPCs) described device tokens hard-bound to security silicon (Secure Enclave, Titan M2) as the industry’s “Custom-Built Bank Vault.” A fingerprint press on a device whose keys never leave its hardware is a stronger authorization signal than a chat approval on a shared phone. That is what issuers and networks need before they shift liability for agent transactions.

Meta has not disclosed the Charm’s security architecture. Zuckerberg did not even say how it connects to Meta’s servers. The strategic logic holds, but whether the hardware delivers it is still unknown.

Consumer Trust Is the Gate

Will consumers link their accounts? Muse is most useful when it holds a lot: payment credentials, logins in its Secure Credential Store, email, calendar, and years of social activity. That is also what consumers are least willing to give. In a Vogue Business survey, only 31% said they would outsource shopping to an AI agent even if it understood their taste. 72% would not share card details, 46% would withhold browsing history, and 40% would not share location (reported by Fortune, Sep 2026). Bain found consumers trust retailer-owned agents three times more than third-party agents to complete a transaction (Bain & Company, “Agentic AI in Retail,” May 2026).

Meta brings its own history, including a $5 billion FTC penalty in 2019. Amazon’s case against Muse rests on the same fear: an agent that stores customer credentials. And Meta’s terms put the risk on the consumer: “You’re responsible for all transactions that your Muse makes on your behalf.”

This is where the Stripe choice helps. Link keeps the card number away from Muse, requires approval of every total in chat, and covers eligible purchases for damage, theft, loss, price drops, and returns. Meta says Muse is the first agent covered by those protections. A consumer who will not give Meta a card number may connect a Stripe wallet. Stripe lends Meta the payment trust it lacks. The Charm is the next step: approval by fingerprint on hardware Meta controls, not a tap in a chat window.

Trust will set the adoption curve. Meta has the product. It still has to earn the linkage.

Where I Was Wrong

On September 8 I wrote that Meta would operate “not closing transactions, but surfacing product-discovery signals to merchant agents,” and that a turnkey shopping agent was “Gemini’s current challenged play.” Muse launched that same day as a turnkey shopping agent that closes transactions.

What I got right is that Meta would not take checkout. What I missed is that Meta did not need checkout to control the transaction. Controlling the agent is enough. It picks the merchant and the credential, then hands the payment to the retailer.

What to Watch

  1. The Walmart payment path. Does Walmart receive Shared Payment Tokens with risk signals, or single-use virtual cards? The answer tells us whether tier-one merchants will accept agent orders at scale.
  2. Credential routing. When a shopper has Link, Shop Pay, PayPal, and a saved card, what does Muse pick, and does placement become something wallets pay for?
  3. Meta’s fee. Rate, payer, and whether it applies to connector retailers or only open-web purchases.
  4. Charm’s security disclosure. Secure element, attestation, and whether a network or issuer recognizes a Charm biometric as strong customer authentication.
  5. Network tokens. Goldman expects Visa and Mastercard agentic tokens to replace the virtual card step. Mastercard Agent Pay is the one construct that places agent transactions inside existing network liability rules.
  6. Amazon’s position. Whether Amazon offers a sanctioned agent path, or holds the line as other horizontal agents arrive.
  7. Link’s funding mix. The share of agent purchases funded by bank account or stablecoin rather than card. That number measures Stripe’s leverage over the networks.
  8. Issuer enrollment. How many US issuers support Mastercard Agent Pay and Visa’s Trusted Agent Protocol by mid-2027, and at what fee.
  9. Linkage rates. How many Muse users connect a payment method and a retailer account, not just download the app.

2 thoughts on “Meta’s Muse: The Agent Becomes the Control Point”

  1. One piece of the Muse/Link economics I can’t quite figure out: what happens when the consumer’s Link funding source is a non-Visa/MC card — say Amex or Discover — but Link issues a single-use virtual card for a non-Link merchant?

    Stripe says those one-time cards are backed by the payment methods in Link, and U.S. Stripe Issuing cards appear to run on Visa/MC. Does that effectively create two card-network legs — e.g., Amex → Link/Stripe, then a Stripe-issued Visa/MC virtual card → merchant? If so, how do interchange, network fees and merchant data work across the two legs, and do the funding network’s staged-wallet rules apply? Or are the funding mechanics different from a conventional card transaction?

    It seems relevant to your “Stripe abstracts the network” thesis — the consumer’s card network would carry only the funding leg, while a different network carries the retail transaction.

    • Very hard to list all the UC here. Quick summary Stripe abstracts the network from the agent and merchant integration layer, but does not abstract the network out of the underlying credit-card transaction (it can’t). The SPT is effectively a common Stripe abstraction that gets translated back into the appropriate network’s agentic credential/rules at execution. For stripe merchants this is all invisible, as SPTs are resolved to each network for authorization and processing. For non stripe merchants the SPT must be resolved into the a form that the merchant can use for its own processing. See my blog on Google SPA https://blog.starpointllp.com/2024/08/google-secure-payment-authentication-spa/

      Back to back transactions have typically been restricted as Issuers like their “brand” at the POS. For example Google Wallet in 2012 ran as all cards within a mastercard and Visa issued a “cease and desist” at the behest of JPM (2012 see this old blog https://blog.starpointllp.com/2012/10/dont-wrap-me/) . Stripe’s SPT must integrate to Visa’s TAP to take advantage of network rules same with Amex ACE to take advantage of Amex rules (amex has a unique incentive with liability shift for qualified agentic transactions). In Europe, back to back has been in place, for example Curve Card which I wrote about, but it never made it to the US and was blocked. SPTs to a stablecoin or bank ACH is also clear.

      1. Stripe merchant
      Muse → SPT → Stripe → network-specific agent credential → issuer
      The merchant doesn’t need to know whether the consumer has Visa, Mastercard, Amex, etc. Stripe resolves the SPT into the appropriate underlying payment/network construct. Stripe explicitly says sellers interact only with SPTs while it handles provisioning agentic network tokens behind the scenes. Stripe
      That makes SPT genuinely analogous to a Stripe-level abstraction above the networks.

      2. Non-Stripe merchant
      Muse → SPT → resolution/provisioning → merchant-usable credential → merchant’s PSP/acquirer → network → issuer
      Here Stripe can’t simply hand the merchant an SPT and expect the merchant’s existing payment stack to understand it. Something has to translate that SPT into a credential the merchant/acquirer can process.

Please Login to Comment.